CVE-2017-14604
nautilus: Insufficient validation of trust of .desktop files with execute permission
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute permission. The solution is to ask the user to confirm that the file is supposed to be treated as a .desktop file, and then remember the user's answer in the metadata::trusted field.
GNOME Nautilus en versiones anteriores a la 3.23.90 permite que los atacantes suplanten un tipo de archivo mediante la extensión de archivo .desktop, tal y como se ve en un ataque en el cual el nombre de un archivo .desktop acaba en .pdf, pero el campo Exec de este archivo lanza un comando "sh-c" malicioso. En otras palabras, Nautilus no proporciona ninguna indicación en la interfaz de usuario sobre si un archivo tiene realmente la extensión .desktop. En lugar de eso, la interfaz de usuario sólo muestra la extensión .pdf. Un factor de mitigación (leve) es que un ataque requiere que el archivo .desktop tenga permisos de ejecución. La solución es pedirle al usuario que confirme que el archivo debe ser tratado como un .desktop y después recordar la respuesta del usuario en el campo metadata::trusted.
An untrusted .desktop file with executable permission set could choose its displayed name and icon, and execute commands without warning when opened by the user. An attacker could use this flaw to trick a user into opening a .desktop file disguised as a document, such as a PDF, and execute arbitrary commands.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-20 CVE Reserved
- 2017-09-20 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-11-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101012 | Third Party Advisory | |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860268 | Issue Tracking | |
https://github.com/freedomofpress/securedrop/issues/2238 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://micahflee.com/2017/04/breaking-the-security-model-of-subgraph-os | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/GNOME/nautilus/commit/1630f53481f445ada0a455e9979236d31a8d3bb0 | 2020-08-18 | |
https://github.com/GNOME/nautilus/commit/bc919205bf774f6af3fa7154506c46039af5a69b | 2020-08-18 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3994 | 2020-08-18 | |
https://access.redhat.com/errata/RHSA-2018:0223 | 2020-08-18 | |
https://bugzilla.gnome.org/show_bug.cgi?id=777991 | 2020-08-18 | |
https://access.redhat.com/security/cve/CVE-2017-14604 | 2018-01-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1490872 | 2018-01-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Nautilus Search vendor "Gnome" for product "Nautilus" | < 3.23.90 Search vendor "Gnome" for product "Nautilus" and version " < 3.23.90" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|